Using automated individual white list to protect web digital identities
Article
Article Title | Using automated individual white list to protect web digital identities |
---|---|
ERA Journal ID | 17852 |
Article Category | Article |
Authors | Han, Weili (Author), Cao, Ye (Author), Bertino, Elisa (Author) and Yong, Jianming (Author) |
Journal Title | Expert Systems with Applications |
Journal Citation | 39 (15), pp. 11861-11869 |
Number of Pages | 9 |
Year | 2012 |
Publisher | Elsevier |
Place of Publication | Oxford, United Kingdom |
ISSN | 0957-4174 |
1873-6793 | |
Digital Object Identifier (DOI) | https://doi.org/10.1016/j.eswa.2012.02.020 |
Abstract | The theft attacks of web digital identities, e.g. phishing, and pharming, could result in severe loss to users and vendors, and even hold users back from using online services, e-business services, especially. In this paper, we propose an approach, referred to as automated individual white-list (AIWL), to protect user's web digital identities. AIWL leverages a Naive Bayesian classifier to automatically maintain an individual white-list of a user. If the user tries to submit his or her account information to a web site that does not match the white-list, AIWL will alert the user of the possible attack. Furthermore, AIWL keeps track of the features of login pages (e.g., IP addresses, document object model (DOM) paths of input widgets) in the individual white-list. By checking the legitimacy of these features, AIWL can efficiently defend users against hard attacks, especially pharming, and even dynamic pharming. Our experimental results and user studies show that AIWL is an efficient tool for protecting web digital identities. |
Keywords | anti-pharming; anti-phishing; identity theft; individual white-list; naive Bayesian classifier; web digital identity |
ANZSRC Field of Research 2020 | 460401. Cryptography |
460499. Cybersecurity and privacy not elsewhere classified | |
460612. Service oriented computing | |
Public Notes | Files associated with this item cannot be displayed due to copyright restrictions. |
Byline Affiliations | Fudan University, China |
Purdue University, United States | |
School of Information Systems | |
Institution of Origin | University of Southern Queensland |
https://research.usq.edu.au/item/q15z8/using-automated-individual-white-list-to-protect-web-digital-identities
1946
total views11
total downloads0
views this month0
downloads this month